BIND 9.x STIG Version Comparison
BIND 9.x Security Technical Implementation Guide
Comparison
There are 123 differences between versions v2 r3 (May 15, 2024) (the "left" version) and v3 r1 (July 14, 2025) (the "right" version).
Check BIND-9X-001180 was added to the benchmark in the "right" version.
This check's original form is available here.
Text Differences
Title
The read and write access to a TSIG key file used by a BIND 9.x server must be restricted to only the account that runs the name server software.
Check Content
Verify permissions assigned to the TSIG keys enforce read-write access to the key owner and deny access to group or system users. With the assistance of the DNS administrator, determine the location of the TSIG keys used by the BIND 9.x implementation: # ls -al <TSIG_Key_Location> -rw-r-----. 1 root named 76 May 10 20:35 tsig-example.key If the key files are more permissive than 640, this is a finding.
Discussion
Weak permissions of a TSIG key file could allow an adversary to modify the file, thus defeating the security objective.
Fix
Change the permissions of the TSIG key files: # chmod 640 <TSIG_key_file>